IM
IronMonkey Threat Research

CVE-2023-1711 MEDIUM

Published: 2023-05-30 | Last Modified: 2024-11-21 | Status: Modified

Description

A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential information. List of CPEs: * cpe:2.3:a:hitachienergy:foxman_un:R9C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman_un:R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman_un:R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman_un:R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman_un:R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman_un:R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman_un:R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman_un:R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:foxman_un:R16A:*:*:*:*:*:*:* * * cpe:2.3:a:hitachienergy:unem:R9C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy: unem :R10C:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy: unem :R11A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy: unem :R11B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy: unem :R14A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy: unem :R14B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy: unem :R15A:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy: unem :R15B:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy: unem :R16A:*:*:*:*:*:*:*

CVSS Metrics

Base Score: 4.4 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 0.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-117
[email protected] Primary
en CWE-116

Affected Products

Vendor Product Version Update Type
hitachienergy foxman-un r9c <built-in method update of dict object at 0x72a9994ab540> Application
hitachienergy foxman-un r10c <built-in method update of dict object at 0x72a9cc4244c0> Application
hitachienergy foxman-un r11a <built-in method update of dict object at 0x72a99a7f2b80> Application
hitachienergy foxman-un r11b <built-in method update of dict object at 0x72a9cc724ac0> Application
hitachienergy foxman-un r14a <built-in method update of dict object at 0x72a9994aa6c0> Application
hitachienergy foxman-un r14b <built-in method update of dict object at 0x72a9994a80c0> Application
hitachienergy foxman-un r15a <built-in method update of dict object at 0x72a9cc424200> Application
hitachienergy foxman-un r15b <built-in method update of dict object at 0x72a9994a9c40> Application
hitachienergy foxman-un r16a <built-in method update of dict object at 0x72a9cc55f340> Application
hitachienergy unem r9c <built-in method update of dict object at 0x72a9994a9680> Application
hitachienergy unem r10c <built-in method update of dict object at 0x72a9994ab2c0> Application
hitachienergy unem r11a <built-in method update of dict object at 0x72a9cc55cfc0> Application
hitachienergy unem r11b <built-in method update of dict object at 0x72a9b0b11280> Application
hitachienergy unem r14a <built-in method update of dict object at 0x72a9b0d23f00> Application
hitachienergy unem r14b <built-in method update of dict object at 0x72a9cc5e4e40> Application
hitachienergy unem r15a <built-in method update of dict object at 0x72a9994a9240> Application
hitachienergy unem r15b <built-in method update of dict object at 0x72a9994a9dc0> Application
hitachienergy unem r16a <built-in method update of dict object at 0x72a9cc426c40> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:hitachienergy:foxman-un:r9c:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:foxman-un:r10c:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:foxman-un:r11a:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:foxman-un:r11b:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:foxman-un:r14a:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:foxman-un:r14b:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:foxman-un:r15a:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:foxman-un:r15b:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:foxman-un:r16a:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:unem:r9c:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:unem:r10c:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:unem:r11a:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:unem:r11b:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:unem:r14a:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:unem:r14b:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:unem:r15a:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:unem:r15b:*:*:*:*:*:*:*
Yes cpe:2.3:a:hitachienergy:unem:r16a:*:*:*:*:*:*:*
Notification
Message here